Mustang Panda Deploys SnakeDisk Malware to Target Thai IPs and Deliver Yokai Backdoor

346/68 Wednesday, September 17, 2025 Cybersecurity researchers from IBM X-Force have revealed that Mustang Panda, a China-linked state-sponsored threat group, is leveraging several new malware variants in its campaigns. Most notably, the group has introduced a new USB worm called SnakeDisk, designed to propagate infections and deliver the Yokai backdoor, enabling remote control of compromised […]

ThaiCERT

September 17, 2025

UK ICO Finds Students Responsible for Majority of School Data Breaches

345/68 Tuesday, September 16, 2025 The UK Information Commissioner’s Office (ICO) has revealed in a new report that students were responsible for more than half of all school-related data breaches in the country, accounting for 57% of incidents. Strikingly, over 97% of cases involving stolen user account data originated from students themselves. Many incidents stemmed […]

ThaiCERT

September 16, 2025

VoidProxy: New Phishing Service Bypasses MFA to Target Microsoft and Google Accounts

344/68 Tuesday, September 16, 2025 Okta Threat Intelligence has uncovered a new phishing platform called VoidProxy, categorized as Phishing-as-a-Service (PhaaS). It provides cybercriminals with a full toolkit to conduct attacks, with a key capability being its ability to bypass Multi-Factor Authentication (MFA) for Microsoft and Google accounts using an Adversary-in-the-Middle (AitM) technique to intercept sensitive […]

ThaiCERT

September 16, 2025

ShinyHunters Hackers Breach Vietnam’s National Credit Information Center

343/68 Tuesday, September 16, 2025 The ShinyHunters hacking group has successfully breached the systems of the National Credit Information Center of Vietnam (CIC). Investigators confirmed evidence of unauthorized access, with leaked data containing sensitive customer information tied to several leading Vietnamese financial institutions, including VietCredit, MB Bank, Ocean Bank, VPBank, and Agribank. Authorities in Vietnam, […]

ThaiCERT

September 16, 2025

Samsung Releases Patch for Critical Zero-Day Vulnerability CVE-2025-21043 on Android

342/68 Monday, September 15, 2025 Samsung has released its monthly Android security update, which includes a fix for the critical zero-day vulnerability CVE-2025-21043 (CVSS 8.8). The flaw is an out-of-bounds write in the libimagecodec.quram.so library that could allow attackers to execute remote malicious code. According to a 2020 report by Google Project Zero, libimagecodec.quram.so is […]

ThaiCERT

September 15, 2025

FBI Warns of Salesforce Attacks by UNC6040 and UNC6395

341/68 Monday, September 15, 2025 The U.S. Federal Bureau of Investigation (FBI) has issued a Flash Alert warning of ongoing cyberattacks by two groups, UNC6040 and UNC6395, which are increasingly targeting the Salesforce platform. The primary objective of these campaigns is to steal sensitive organizational data and conduct extortion. The alert also includes Indicators of […]

ThaiCERT

September 15, 2025

“HybridPetya”: New Ransomware Capable of Bypassing UEFI Secure Boot

340/68 Monday, September 15, 2025 Researchers have uncovered a new ransomware strain called “HybridPetya”, which merges features of the infamous Petya and NotPetya malware that caused devastating outbreaks in 2016–2017. The alarming aspect of HybridPetya lies in its ability to bypass the UEFI Secure Boot security mechanism, enabling it to implant malicious code into the […]

ThaiCERT

September 15, 2025

“RatOn” Android Malware Uses NFC Relay and ATS Techniques to Target Banks and Crypto

339/68 Friday, September 12, 2025 Security researchers from the Netherlands have uncovered a new Android malware strain called RatOn, which evolved from NFC relay tools into a sophisticated Remote Access Trojan (RAT). RatOn is equipped with Automated Transfer System (ATS) capabilities to manipulate financial transactions, combining features such as overlay attacks, automated transfers, and NFC […]

ThaiCERT

September 12, 2025

KillSec Ransomware Attacks MedicSolution, Compromises Healthcare Data in Brazil

338/68 Friday, September 12, 2025 The KillSec ransomware group has claimed responsibility for a cyberattack against MedicSolution, a Brazilian healthcare software provider, threatening to leak stolen data if negotiations are not initiated. According to a report by Resecurity, the incident stemmed from data exfiltration via an unsecured AWS S3 bucket, which had been left exposed […]

ThaiCERT

September 12, 2025

Warning: Akira Ransomware Gang Exploits SonicWall Vulnerabilities to Target Organizations Worldwide

337/68 Friday, September 12, 2025 Cybersecurity experts at Rapid7 have issued an urgent warning about escalating cyberattacks, as the Akira ransomware group has resumed exploiting vulnerabilities in SonicWall appliances. These include critical flaws that were already abused last year. Contrary to earlier suspicions of a new zero-day exploit, the attacks are leveraging known vulnerabilities such […]

ThaiCERT

September 12, 2025
1 13 14 15 56